merfin993
merfin993
@doomedraven Hi, I'm luca the colleague of simone.co. I apologize for the delayed reply. We tried to do some debugging and all signatures seem to be running correctly. (the conditions...
ok, we'll test soon
Hi @hasherezade, thanks for the reply. The setting that doesn't run the payload with Tiny_Tracer (vmprotect demo latest version)  And the sample [sample.zip](https://github.com/hasherezade/tiny_tracer/files/10310845/sample.zip) (Password "infected") You will find the...
Hi @hasherezade. Today I was able (with a driver) to get trace of system calls used by vmprotect with usermode and usermode + kernelmode antidebug flags enabled. I wanted to...
Hi @hasherezade. I did some tests by disabling virtualization and mutations to get the cleanest trace possible. (the sample is contained in the archive) Using a driver to get syscall...